Vendor
high
advisory
Stored XSS in BestWebSoft Contact Form to DB Plugin
1 rule 1 TTP 1 CVEThe Contact Form to DB WordPress plugin (<= 1.7.5) is vulnerable to unauthenticated Stored Cross-Site Scripting via the cntctfrm_contact_dropdown parameter, allowing attackers to execute scripts in an administrator's browser session.
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress
web-application
xss
wordpress
cve-2026-13359
1r
1t
1c
high
advisory
SQL Injection in The Gallery by BestWebSoft WordPress Plugin
1 TTP 1 CVEThe Gallery by BestWebSoft plugin for WordPress up to version 4.7.9 contains an SQL injection vulnerability via the '_gallery_order_{post_id}' parameter allowing authenticated attackers with Editor-level access to extract database information.
The Gallery
web-application-vulnerability
wordpress
sqli
1t
1c